From owner-freebsd-jail@FreeBSD.ORG Sun Feb 13 13:28:21 2011 Return-Path: Delivered-To: freebsd-jail@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 50B3A106564A for ; Sun, 13 Feb 2011 13:28:21 +0000 (UTC) (envelope-from rickvanderzwet@gmail.com) Received: from mail-vw0-f54.google.com (mail-vw0-f54.google.com [209.85.212.54]) by mx1.freebsd.org (Postfix) with ESMTP id 089168FC13 for ; Sun, 13 Feb 2011 13:28:20 +0000 (UTC) Received: by vws9 with SMTP id 9so2476024vws.13 for ; Sun, 13 Feb 2011 05:28:20 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:mime-version:sender:in-reply-to:references:date :x-google-sender-auth:message-id:subject:from:to:cc:content-type; bh=awXQy4Li5YI0rTQRhQ4kVnSZQwGFxTCOY5y3+NxJVK8=; b=MQ9ofJd+9NbuQp+r0/tCf9D+VZMGBNIBhkrQg/CdZcHWaKnJoVijwJg0r7Lrf0t5cn LM9H6R03EsjWs7HXyf8DF7AA8CX4/cZ+cxQ388e9S6OqJdy28K29zGZ/mlp1HDP97q// ykInMEnPGJQXjjphoOcnpoicYVbYu2QqPyLOU= DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=mime-version:sender:in-reply-to:references:date :x-google-sender-auth:message-id:subject:from:to:cc:content-type; b=xHQpn7BEgzDX1Kv4Fm6fUzXXTm/6tjU6niMjHJyM3+3luaS5Q59dRBZSxibWKPBEAK A9Vh2n27lNv4JN6lfDd/G8yuP4ruX1DH9qQDldArpezo0ECkrwSBZSwKZ1ZinkWf8+IM pHb0OCfGXzRdNU3cDpcajRd+lYooFWHG1QN1o= MIME-Version: 1.0 Received: by 10.220.192.138 with SMTP id dq10mr3405246vcb.259.1297602336846; Sun, 13 Feb 2011 05:05:36 -0800 (PST) Sender: rickvanderzwet@gmail.com Received: by 10.220.117.66 with HTTP; Sun, 13 Feb 2011 05:05:36 -0800 (PST) In-Reply-To: <427773.20226.qm@web111717.mail.gq1.yahoo.com> References: <427773.20226.qm@web111717.mail.gq1.yahoo.com> Date: Sun, 13 Feb 2011 14:05:36 +0100 X-Google-Sender-Auth: qpmDk-uSwbELYBqyCkAQdoidbY8 Message-ID: From: Rick van der Zwet To: Steve Wong Content-Type: text/plain; charset=ISO-8859-1 Cc: freebsd-jail@freebsd.org Subject: Re: Gnome & Vino binding to all IP Addresses X-BeenThere: freebsd-jail@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Discussion about FreeBSD jail\(8\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 13 Feb 2011 13:28:21 -0000 On 11 February 2011 23:03, Steve Wong wrote: > I have a workstation which I want to have gnome desktop and the vino-server (vnc > server) running, and a few jails created to run other services. Neither vino-server or gnome desktop are part of the FreeBSD base operating system. It is slightly out of the scope IMHO of this mailinglist to answer how-to configure specific applications to bound to a single IP or interface only. > While I have configured other daemons such as sshd to listen only to the host's IP address, I > don't know how to configure gnome or its vino-server to listen only 1 IP address. This is preventing > ezjail from creating any jails. Any help is appreciated. The base system running the jail should by design no have many unbound daemons running, basically only bounded sshd and some other bare (bounded) 'minimum' servers.. Also have not seen many cases somebody using a FreeBSD desktop and running jails on them as well. You are best trying the documentation (gnome, vino-server), to see how to make them bound to a fixed address/interface to make it work correctly. Br. /Rick -- http://rickvanderzwet.nl From owner-freebsd-jail@FreeBSD.ORG Mon Feb 14 11:07:07 2011 Return-Path: Delivered-To: freebsd-jail@FreeBSD.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 2BC7F1065697 for ; Mon, 14 Feb 2011 11:07:07 +0000 (UTC) (envelope-from owner-bugmaster@FreeBSD.org) Received: from freefall.freebsd.org (freefall.freebsd.org [IPv6:2001:4f8:fff6::28]) by mx1.freebsd.org (Postfix) with ESMTP id 184278FC23 for ; Mon, 14 Feb 2011 11:07:07 +0000 (UTC) Received: from freefall.freebsd.org (localhost [127.0.0.1]) by freefall.freebsd.org (8.14.4/8.14.4) with ESMTP id p1EB76mp077217 for ; Mon, 14 Feb 2011 11:07:06 GMT (envelope-from owner-bugmaster@FreeBSD.org) Received: (from gnats@localhost) by freefall.freebsd.org (8.14.4/8.14.4/Submit) id p1EB761d077214 for freebsd-jail@FreeBSD.org; Mon, 14 Feb 2011 11:07:06 GMT (envelope-from owner-bugmaster@FreeBSD.org) Date: Mon, 14 Feb 2011 11:07:06 GMT Message-Id: <201102141107.p1EB761d077214@freefall.freebsd.org> X-Authentication-Warning: freefall.freebsd.org: gnats set sender to owner-bugmaster@FreeBSD.org using -f From: FreeBSD bugmaster To: freebsd-jail@FreeBSD.org Cc: Subject: Current problem reports assigned to freebsd-jail@FreeBSD.org X-BeenThere: freebsd-jail@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Discussion about FreeBSD jail\(8\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 14 Feb 2011 11:07:07 -0000 Note: to view an individual PR, use: http://www.freebsd.org/cgi/query-pr.cgi?pr=(number). The following is a listing of current problems submitted by FreeBSD users. These represent problem reports covering all versions including experimental development code and obsolete releases. S Tracker Resp. Description -------------------------------------------------------------------------------- o conf/154246 jail [jail] [patch] Bad symlink created if devfs mount poin o conf/150599 jail [patch] /etc/rc.d/jail does not set jailname. o conf/149050 jail [jail] rcorder ``nojail'' too coarse for Jail+VNET s conf/142972 jail [jail] [patch] Support JAILv2 and vnet in rc.d/jail o conf/141317 jail [patch] uncorrect jail stop in /etc/rc.d/jail o kern/133265 jail [jail] is there a solution how to run nfs client in ja o kern/119842 jail [smbfs] [jail] "Bad address" with smbfs inside a jail o bin/99566 jail [jail] [patch] fstat(1) according to specified jid o bin/32828 jail [jail] w(1) incorrectly handles stale utmp slots with 9 problems total. From owner-freebsd-jail@FreeBSD.ORG Wed Feb 16 17:03:54 2011 Return-Path: Delivered-To: freebsd-jail@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 93BFD106564A for ; Wed, 16 Feb 2011 17:03:54 +0000 (UTC) (envelope-from monthadar@gmail.com) Received: from mail-ww0-f50.google.com (mail-ww0-f50.google.com [74.125.82.50]) by mx1.freebsd.org (Postfix) with ESMTP id 2F73C8FC18 for ; Wed, 16 Feb 2011 17:03:53 +0000 (UTC) Received: by wwf26 with SMTP id 26so1552529wwf.31 for ; Wed, 16 Feb 2011 09:03:53 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:mime-version:date:message-id:subject:from:to :content-type; bh=dFc8o2BO9p3BaMp/8T33TOZ4MOi8s2aoskAegd61vxM=; b=SgVnA45k0xTj6Mys4hVYVBe1KGzqORVuqeIE0jXz/C+bupbmnl35AT90ZklPo0X5mA sR47O4C6vmMC76bScnOw5EHTNN9Zoo3A/gQql8zNESrQ81OtB+WIjoKV3Nc7xNDZciCC jK8JUEJfv53Qwd1ayr9bB2QrIPeXEzvu8zfZM= DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=mime-version:date:message-id:subject:from:to:content-type; b=MvlzKqV9lMHwmtJSyp47cQV/DuRYo85CwhgK+kZVd1t3bDRTgRU34jD25RmaHgQO3J IczKCP8Q0mo9vNh2dbaJSutogb0SDzsGrZhslubUBdNmbsxmQCx9IkBnxeoxVQLZJloM H4X1ERjZ2Fs+W8x9lPrznCJCltT1/vZ5DSnNA= MIME-Version: 1.0 Received: by 10.227.144.212 with SMTP id a20mr711766wbv.103.1297874086667; Wed, 16 Feb 2011 08:34:46 -0800 (PST) Received: by 10.227.69.7 with HTTP; Wed, 16 Feb 2011 08:34:46 -0800 (PST) Date: Wed, 16 Feb 2011 17:34:46 +0100 Message-ID: From: Monthadar Al Jaberi To: freebsd-jail@freebsd.org Content-Type: text/plain; charset=ISO-8859-1 Subject: [jail][vnet] wlandebug inside jail, operation not permitted X-BeenThere: freebsd-jail@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Discussion about FreeBSD jail\(8\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 16 Feb 2011 17:03:54 -0000 Hej, I have created a jail with "jail -c jid=1 vnet persist", then moved a wlan to it "ifconfig wlan0 vnet 1" but when I try to run: "jexec 1 wlandebug -i wlan0 state" I get : wlandebug: sysctl-set(net.wlan.0.debug): Operation not permitted net.wlan.0.debug: 0x22000 => I can run wlandebug before moving wlan to a jail, but why cant I do it inside the jail? I am running everything as root. thank you in advance, -- //Monthadar Al Jaberi From owner-freebsd-jail@FreeBSD.ORG Wed Feb 16 21:13:32 2011 Return-Path: Delivered-To: freebsd-jail@FreeBSD.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 6840E1065679 for ; Wed, 16 Feb 2011 21:13:32 +0000 (UTC) (envelope-from jamie@FreeBSD.org) Received: from gritton.org (gritton.org [208.92.232.93]) by mx1.freebsd.org (Postfix) with ESMTP id 2E26E8FC1E for ; Wed, 16 Feb 2011 21:13:31 +0000 (UTC) Received: from guppy.corp.verio.net (fw.oremut02.us.wh.verio.net [198.65.168.24]) (authenticated bits=0) by gritton.org (8.14.3/8.14.3) with ESMTP id p1GLDU1F014273; Wed, 16 Feb 2011 14:13:31 -0700 (MST) (envelope-from jamie@FreeBSD.org) Message-ID: <4D5C3DF8.9080009@FreeBSD.org> Date: Wed, 16 Feb 2011 14:13:28 -0700 From: Jamie Gritton User-Agent: Mozilla/5.0 (X11; U; FreeBSD amd64; en-US; rv:1.9.2.12) Gecko/20110107 Thunderbird/3.1.6 MIME-Version: 1.0 To: Monthadar Al Jaberi References: In-Reply-To: Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit Cc: freebsd-jail@FreeBSD.org Subject: Re: [jail][vnet] wlandebug inside jail, operation not permitted X-BeenThere: freebsd-jail@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Discussion about FreeBSD jail\(8\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 16 Feb 2011 21:13:32 -0000 This is by design. The "root" in a jail isn't quite a full-featured root, and in particular can't do anything that affects the hardware in ways beyond normal non-administrative use. - Jamie On 02/16/11 09:34, Monthadar Al Jaberi wrote: > Hej, > > I have created a jail with "jail -c jid=1 vnet persist", then moved a > wlan to it "ifconfig wlan0 vnet 1" but when I try to run: > "jexec 1 wlandebug -i wlan0 state" I get : > > wlandebug: sysctl-set(net.wlan.0.debug): Operation not permitted > net.wlan.0.debug: 0x22000 => > > I can run wlandebug before moving wlan to a jail, but why cant I do it > inside the jail? I am running everything as root. > > > thank you in advance, > From owner-freebsd-jail@FreeBSD.ORG Wed Feb 16 21:13:37 2011 Return-Path: Delivered-To: freebsd-jail@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 421B41065670 for ; Wed, 16 Feb 2011 21:13:37 +0000 (UTC) (envelope-from rickvanderzwet@gmail.com) Received: from mail-qy0-f182.google.com (mail-qy0-f182.google.com [209.85.216.182]) by mx1.freebsd.org (Postfix) with ESMTP id EB0318FC1C for ; Wed, 16 Feb 2011 21:13:36 +0000 (UTC) Received: by qyg14 with SMTP id 14so998762qyg.13 for ; Wed, 16 Feb 2011 13:13:36 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:mime-version:sender:in-reply-to:references:date :x-google-sender-auth:message-id:subject:from:to:cc:content-type; bh=6rGu9be9TlPEjPe4M6jZrJsew91R208X/4fby2KR9Hk=; b=dQXlbF+5kzzlVR/GUeHdVlI8U2NhZrGUIH0bYhwkFUv+8vz84rUgAossqafz7jy2BR CpeZeG8lV9GxO1+aaFboCIJpCawB3wRsQQcjUp2FCpk9LLiA8AQUsoDl9+xSpieTEpEh PpVVbQgT8itCWmB2LepwIgNWQDoEEbYwPK518= DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=mime-version:sender:in-reply-to:references:date :x-google-sender-auth:message-id:subject:from:to:cc:content-type; b=NczJlSn05A1CUlrCgAjvvKHH62OHzSz6lVQaplx5YE2ZarRn2H0B9p4HR2RKc6qWot 4MfJJ+AC6Ty9+KiXEnvKQ0RL/cv+6hmX3e8EOD6zvKt5thSQZlE2tDhZqRxFXnHnI1RH FvoByqN/o50uQ9vYQ5R9x3zf24knrTN1aSSl4= MIME-Version: 1.0 Received: by 10.224.45.68 with SMTP id d4mr1451008qaf.115.1297890815706; Wed, 16 Feb 2011 13:13:35 -0800 (PST) Sender: rickvanderzwet@gmail.com Received: by 10.220.11.78 with HTTP; Wed, 16 Feb 2011 13:13:35 -0800 (PST) In-Reply-To: References: Date: Wed, 16 Feb 2011 22:13:35 +0100 X-Google-Sender-Auth: QVqlPlYdAnOz9PBjKQUjZO0URf0 Message-ID: From: Rick van der Zwet To: Monthadar Al Jaberi Content-Type: text/plain; charset=ISO-8859-1 Cc: freebsd-jail@freebsd.org Subject: Re: [jail][vnet] wlandebug inside jail, operation not permitted X-BeenThere: freebsd-jail@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Discussion about FreeBSD jail\(8\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 16 Feb 2011 21:13:37 -0000 On 16 February 2011 17:34, Monthadar Al Jaberi wrote: > I have created a jail with "jail -c jid=1 vnet persist", then moved a > wlan to it "ifconfig wlan0 vnet 1" but when I try to run: > "jexec 1 wlandebug -i wlan0 state" I get : > > wlandebug: sysctl-set(net.wlan.0.debug): Operation not permitted > net.wlan.0.debug: 0x22000 => > > I can run wlandebug before moving wlan to a jail, but why cant I do it > inside the jail? I am running everything as root. You cannot control your device drivers from a jail. I am even wondering why you try to do this commands inside a jail in the first place. Please have a look at the handbook page: http://www.freebsd.org/doc/handbook/jails.html to see the intended usage of jails and what is possible and not. Br. /Rick -- http://rickvanderzwet.nl From owner-freebsd-jail@FreeBSD.ORG Thu Feb 17 09:30:14 2011 Return-Path: Delivered-To: freebsd-jail@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 7BD091065672 for ; Thu, 17 Feb 2011 09:30:14 +0000 (UTC) (envelope-from monthadar@gmail.com) Received: from mail-ww0-f50.google.com (mail-ww0-f50.google.com [74.125.82.50]) by mx1.freebsd.org (Postfix) with ESMTP id 118F58FC0A for ; Thu, 17 Feb 2011 09:30:13 +0000 (UTC) Received: by wwf26 with SMTP id 26so2298356wwf.31 for ; Thu, 17 Feb 2011 01:30:12 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:mime-version:in-reply-to:references:date :message-id:subject:from:to:cc:content-type; bh=58hOb9o8MJ91/qkm9kx99xJ0FODiI+4BfSCZ27ys4CU=; b=Wttj4ZwJLP+uBWv8XUtzXQhAz7uskObsTOSaqwhMj+UsLLl1vLUkprdB8clnfjo2U3 I9bxaq6EiiMUt7V36zstJSMPhgshvD18h3M0gXirvZ++GPQPDRWO6yy/Kch7f1tSs9pj R3JoJq3HGnfMWiJBuwgRD8zOV+Q18w037SQ5o= DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; b=aCvHTEE+7dz5vfX4C5Y7MPGiGjOVDzwuI+vEMqW0mAWRFHwpCCbQdDyuE3tSw2fb0d gWj7mr42lAXmokjmVfw5XdS4OwZ2n6tsjeMZ0tr+wRHS/Gy+74/bcvJKsxWM2ZNRD0Cb hZinOrBYk+McbuLNh+WQda3CQOHtbVPZdiFpk= MIME-Version: 1.0 Received: by 10.227.144.212 with SMTP id a20mr1424931wbv.103.1297935011552; Thu, 17 Feb 2011 01:30:11 -0800 (PST) Received: by 10.227.69.7 with HTTP; Thu, 17 Feb 2011 01:30:11 -0800 (PST) In-Reply-To: References: Date: Thu, 17 Feb 2011 10:30:11 +0100 Message-ID: From: Monthadar Al Jaberi To: Rick van der Zwet , jamie@freebsd.org Content-Type: text/plain; charset=ISO-8859-1 Cc: freebsd-jail@freebsd.org Subject: Re: [jail][vnet] wlandebug inside jail, operation not permitted X-BeenThere: freebsd-jail@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Discussion about FreeBSD jail\(8\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 17 Feb 2011 09:30:14 -0000 Thank you for clarifications. I am using jails like a virtual host, each having its own network stack and a wireless card, I am trying out to test 802.11s mesh code, and sometimes when I find that some scenario is not working I want to turn on debug information to see what is happening, it is hard to guess before hand =) So is it easy to change so that I can give a jail this permission? I know I am not using it like it was intended, for me I create sometimes 64 jails with each network stack and a virtual wireless driver and test the code, so it is hard to know which node I want to debug beforehand. thank you, On Wed, Feb 16, 2011 at 10:13 PM, Rick van der Zwet wrote: > On 16 February 2011 17:34, Monthadar Al Jaberi wrote: >> I have created a jail with "jail -c jid=1 vnet persist", then moved a >> wlan to it "ifconfig wlan0 vnet 1" but when I try to run: >> "jexec 1 wlandebug -i wlan0 state" I get : >> >> wlandebug: sysctl-set(net.wlan.0.debug): Operation not permitted >> net.wlan.0.debug: 0x22000 => >> >> I can run wlandebug before moving wlan to a jail, but why cant I do it >> inside the jail? I am running everything as root. > > You cannot control your device drivers from a jail. I am even > wondering why you try to do this commands inside a jail in the first > place. > > Please have a look at the handbook page: > http://www.freebsd.org/doc/handbook/jails.html to see the intended > usage of jails and what is possible and not. > > Br. /Rick > -- > http://rickvanderzwet.nl > -- //Monthadar Al Jaberi